On 6.8, when using Asset-Based Session Access. in Access Request Policy | Access Config. After adding an account into "Directory Account", and clicking on OK or Apply, other undesired accounts are automatically added. Attempting to remove these accounts fail, and they are re-added.
Safeguard appears to be adding Directory Accounts previously removed from the Access Request Policy.
Remove the problematic Access Request Policy. Then recreate the Entitlement with a new Access Request Policy.